Published Oct 27, 2022

Never pay the ransom — a cybersecurity CEO explains why

Explore the escalating challenge of ransomware in healthcare with Steve Cagle, CEO of Clearwater Compliance, as he provides insights on risk management, the role of cryptocurrency in cyber attacks, and the critical strategies to fortify cybersecurity measures while navigating industry consolidation.
Episode Highlights
Decoder with Nilay Patel logo

Popular Clips

Episode Highlights

  • Risk Management

    Risk management in healthcare is a continuous process, crucial for safeguarding sensitive data and ensuring operational integrity. emphasizes that risk management involves identifying critical information assets and assessing potential threats, including insider threats, which are a significant concern in the healthcare sector 1. He explains that ongoing activities like penetration testing and vulnerability management are essential components of a robust risk management program 1.

    When you're thinking about cybersecurity risk, you have to start by thinking about the assets that we have, information assets. These are not necessarily physical assets. It's data that's very sensitive, that's very valuable, and people want to get to it.

    ---

    Clearwater Compliance differentiates itself by leveraging its deep understanding of healthcare regulations and offering managed services that transition organizations from point-in-time assessments to continuous risk management 2.

       

    Compliance

    Compliance with regulations like HIPAA is a cornerstone of cybersecurity efforts in healthcare. notes that while HIPAA was initially a major driver for compliance, the focus has shifted towards broader cybersecurity measures due to evolving threats and additional state regulations 3. He highlights the importance of protecting electronic protected health information (ePHI), which is highly valuable on the dark web due to its comprehensive nature 4.

    A electronic protected health record on the dark web could be up to $1,000 a record, as opposed to a Social Security number or a credit card record being a few dollars.

    ---

    The transition from paper to digital records has increased accessibility but also introduced new security challenges, making compliance a complex but essential task 3.

       

    Outsourcing

    Outsourcing cybersecurity functions is becoming a popular strategy among healthcare organizations to manage complex security needs. explains that Clearwater Compliance offers managed services, including acting as a chief information security officer, to help organizations maintain robust security programs without the need for in-house expertise 5. This approach is particularly appealing to fast-growing businesses, such as those backed by private equity, which require scalable and efficient security solutions 6.

    We'll take on the role of chief information security officer for the organization, which is a seasoned executive that has both technical and business experience, and then we'll actually implement and execute their program for them on an ongoing basis.

    ---

    The predictable cost model of these services allows organizations to focus on growth while ensuring their security needs are met 5.

Related Episodes